Privacy Policy
1. Who We Are
KynectLocal operates a multi-tenant Software-as-a-Service platform that enables franchise brands to manage their locations, digital presence, marketing content, lead generation, and operational workflows. The platform serves three categories of users: platform administrators, brand administrators, and franchisee operators.
For the purposes of applicable data protection laws, KynectLocal acts as a data controller with respect to account and platform-usage data, and as a data processor with respect to personal data submitted by customers, leads, and end users on behalf of the brands and franchisees that use our platform.
2. Scope and Applicability
This policy applies to:
- Individuals who create or access a KynectLocal account (brand admins, franchisees, marketing users, platform admins).
- Visitors and end users of public-facing pages and forms hosted through the KynectLocal platform on behalf of brands and franchisees.
- Individuals whose data is submitted to the platform via web forms, lead capture, integration syncs (e.g., CallRail, WhatConverts, HubSpot), or API calls.
If you are a franchisee or brand operator using KynectLocal to collect data from your own customers, you bear independent responsibilities as a data controller for that data. This policy does not replace or override the privacy policies of the brands or franchisees operating on our platform.
3. Data We Collect
3.1 Account and Identity Data
- Full name, email address, and hashed password.
- Role and permission assignments (e.g., brand_admin, franchisee, marketing).
- Profile information: phone number, job title, avatar image URL.
- Invitation metadata: inviter identity, invitation acceptance timestamp, temporary password state.
- Last login timestamp and account status (active, suspended).
3.2 Business and Location Data
- Business name, address, city, state, zip code, country.
- Business phone numbers, website URLs, and social media handles.
- Operating hours, holiday hours, service descriptions, and staff information.
- Location-specific SEO metadata: meta titles, descriptions, canonical URLs, Open Graph images.
- Custom fields defined by brand administrators and values submitted by franchisees.
- Latitude, longitude, and geographic coverage zones.
3.3 Content and Media Data
- Page content, blocks, and layouts created or edited in the visual page builder.
- Blog posts, events, and scheduled publications.
- Media files uploaded to the platform (images, documents) stored via the configured storage provider.
- Email templates, form definitions, and automated response configurations.
- Content tokens and dynamic variable values used in page and email rendering.
3.4 Lead and Form Submission Data
- Name, email, phone number, and any other fields included in form submissions.
- UTM parameters, referrer URLs, and source attribution data captured at submission time.
- Lead quality scores, call tracking data, and conversion events synced from integrated providers.
- External lead identifiers from connected platforms (e.g., CallRail, WhatConverts).
3.5 Usage and Technical Data
- IP addresses, browser type, and device information logged on each API request.
- Request path, HTTP method, response status, and response time (via structured request logs).
- Audit log entries: who did what to which resource, and when.
- AI usage logs: prompt category, token counts, and model used (not prompt content).
- Job queue events: bulk import progress, distribution sync outcomes, email delivery status.
3.6 Billing and Payment Data
- Subscription plan, billing cycle, and license tier (Core, Pro, Enterprise).
- Stripe customer and subscription identifiers. Payment card details are handled entirely by Stripe and are never stored on KynectLocal servers.
- Invoice history, usage meter readings (AI tokens, distribution calls, API requests, storage).
- Entitlement overrides and add-on configurations set by platform administrators.
3.7 Integration Credential Data
- API keys, OAuth tokens, and webhook secrets for connected third-party services (e.g., HubSpot, Calendly, Google Business Profile, Yext, Meta Ads, TikTok Ads, Microsoft Ads, BrightLocal, Soci, CallRail, WhatConverts).
- Integration credentials are stored encrypted at rest using AES-256-GCM.
4. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Authenticating users and maintaining secure sessions | Email, hashed password, JWT tokens, refresh token chain |
| Providing platform features: page builder, content management, SEO tools, analytics | Account data, business/location data, content data |
| Routing public web traffic to the correct brand or location page | Domain names, slug configuration, URL policy settings |
| Rendering and serving public-facing pages and sitemaps | Content items, location profiles, media files, SEO metadata |
| Processing and routing lead submissions | Form submission data, lead data, integration push configurations |
| Sending transactional and marketing emails on behalf of brands | Lead data, email template content, Resend API credentials |
| Syncing data with connected integrations | Lead data, location data, integration credentials |
| Generating AI-assisted content suggestions | Business profile data, service descriptions, prompt context |
| Billing and subscription management | Stripe identifiers, plan data, usage meters |
| Platform security, fraud prevention, and abuse monitoring | IP addresses, request logs, audit log data |
| Improving platform reliability and diagnosing errors | Request logs, error traces, job queue events |
| Complying with legal obligations | Any data required by applicable law |
5. Legal Basis for Processing (GDPR)
For users in the European Economic Area, United Kingdom, and Switzerland, we rely on the following legal bases:
- Contract performance — processing necessary to provide the platform services you have subscribed to.
- Legitimate interests — security monitoring, fraud prevention, platform analytics, product improvement, and audit logging, where these interests are not overridden by your rights.
- Legal obligation — processing required to comply with applicable law, including tax and financial record-keeping obligations.
- Consent — where we specifically request your consent (e.g., optional analytics tracking). You may withdraw consent at any time.
For lead and form submission data processed on behalf of brands and franchisees, the applicable legal basis is determined by and the responsibility of the brand or franchisee acting as data controller.
6. Third-Party Services and Sub-Processors
KynectLocal engages the following categories of sub-processors. We require all sub-processors to maintain appropriate security and privacy standards.
| Provider | Category | Purpose |
|---|---|---|
| Railway | Cloud infrastructure | Hosting API servers, worker processes, and managed PostgreSQL / Redis instances |
| Amazon S3 (via Railway) | Object storage | Media file storage and static asset hosting |
| Stripe | Payment processing | Subscription billing, invoicing, and payment card handling |
| Resend | Email delivery | Transactional emails (invitations, password resets, billing notifications, lead notifications, broadcast emails) |
| Google Gemini (via Google AI) | Artificial intelligence | AI-assisted content generation, SEO suggestions, and analytics chat interface |
| HubSpot | CRM integration (optional) | Pushing lead contact records to connected HubSpot accounts on behalf of brands |
| Calendly | Scheduling integration (optional) | Embedding booking widgets on location pages |
| CallRail | Call tracking (optional) | Syncing call lead data to the platform on behalf of connected brands |
| WhatConverts | Lead tracking (optional) | Syncing conversion lead data to the platform on behalf of connected brands |
| Google Business Profile / Yext / Soci / BrightLocal | Distribution (optional) | Distributing location data to directories and listing platforms (stub integrations) |
| Meta Ads / TikTok Ads / Microsoft Ads | Advertising pixels (optional) | Injecting pixel tracking scripts on public pages on behalf of brands |
| Matomo | Web analytics (optional) | On-premise or cloud analytics tracking on public pages on behalf of brands; configured per brand |
| ioredis / Redis (BullMQ) | Job queue | Background job processing for imports, distribution, email, and usage aggregation |
Optional integrations (marked above) are only active for brands that have explicitly configured and enabled them. Data is not sent to optional third parties unless that integration is active for the relevant brand or location.
8. Franchise and Multi-Tenant Data Handling
KynectLocal is a multi-tenant platform. Each tenant (brand) operates in a logically isolated data environment. All database queries are scoped by tenantId, and cross-tenant data access is prevented at the application layer.
8.1 Brand and Franchisee Relationship
Brand administrators set governance rules that determine which profile fields franchisees can edit independently versus fields that are locked at the brand level. KynectLocal enforces these rules but does not independently determine governance policy — that is set by each brand.
8.2 Location Data
Location data (address, hours, services, contact details, custom fields) is associated with the brand's tenant and is accessible to brand administrators. Franchisees can access only the locations they are explicitly assigned to.
8.3 Platform Administrator Access
KynectLocal super administrators have the technical ability to access all tenant data for the purposes of platform support, security incident investigation, and legal compliance. Such access is logged in the audit trail.
8.4 Data Isolation on Suspension or Termination
When a brand account is suspended, user access is revoked immediately. Data is not automatically deleted and may be retained for the period described in Section 11 (Data Retention) to allow for account recovery or legal compliance.
9. Artificial Intelligence Features
KynectLocal uses Google Gemini (gemini-2.5-flash) to power AI-assisted features including:
- SEO content generation (meta titles, descriptions, llms.txt)
- Service description generation
- Page content suggestions via the Puck editor AI Assist
- The analytics AI chat assistant
9.1 Data Sent to AI Providers
When you use an AI feature, relevant context from your account — such as business name, location, service descriptions, and analytics summaries — is included in the prompt sent to Google Gemini. We do not send payment card data, integration API keys, or end-user personal data (such as lead contact details) to AI providers.
9.2 AI Usage Logging
We log each AI call including: the brand and user who initiated it, the prompt category, the model used, and token counts. Actual prompt and response content is not stored in our logs.
9.3 AI-Generated Content
AI-generated content is a suggestion only. You are responsible for reviewing, editing, and publishing any content generated through AI features. We make no warranties regarding the accuracy, completeness, or suitability of AI-generated output.
9.4 AI Token Limits
AI feature usage is subject to the token limits of your license tier (Core: 10,000 tokens/month; Pro: 100,000 tokens/month; Enterprise: unlimited). Usage is tracked per brand.
11. Data Retention
| Data Type | Retention Period |
|---|---|
| Active account data (user profiles, business data, content) | For the duration of the active subscription, plus 90 days after termination |
| Audit log entries | 24 months from creation (configurable per tenant; auto-purged by scheduled job) |
| Lead and form submission data | Duration of the active subscription; deleted upon account deletion unless legally required to retain |
| AI usage logs | 12 months |
| Request / access logs (structured logs) | 90 days |
| Billing records and invoices | 7 years (legal and tax compliance) |
| Password reset tokens | 1 hour (expire automatically) |
| Refresh tokens | Invalidated on use or logout; orphaned tokens purged after 30 days |
| Bulk import staging data (Redis) | Automatically evicted per Redis TTL configuration |
| Media files (object storage) | Deleted when the associated media record is deleted; orphan cleanup run periodically |
You may request deletion of your personal data at any time (see Section 14). We will honor deletion requests subject to applicable legal holds and our legitimate interest in maintaining audit records.
12. Security Measures
We implement the following technical and organizational measures to protect your data:
- Authentication — RS256 JWT access tokens (15-minute expiry) with rotating refresh tokens. Immediate refresh token invalidation on use prevents replay attacks.
- Password storage — bcrypt hashing with a configurable cost factor (minimum 12 in production).
- Credential encryption — integration API keys and secrets stored using AES-256-GCM symmetric encryption with per-record key derivation.
- Transport security — all data transmitted over HTTPS/TLS. HTTP to HTTPS upgrades enforced.
- Database isolation — all queries are scoped to the authenticated tenant; cross-tenant access is prevented at the application layer.
- Rate limiting — per-IP and per-user rate limits enforced on all API endpoints, backed by Redis.
- Security headers — Helmet.js middleware applies standard HTTP security headers (CSP, HSTS, X-Frame-Options, etc.).
- Audit trail — all material data modifications are written to a tamper-evident audit log.
- Dependency management — regular dependency updates and security patch reviews.
13. International Data Transfers
KynectLocal operates primarily in the United States. If you access the platform from outside the United States, your data will be transferred to, stored, and processed in the United States and potentially other countries where our sub-processors operate.
For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our data processing agreements with sub-processors.
- The EU–US Data Privacy Framework for sub-processors that are certified under it.
If you have questions about international transfers, contact us using the details in Section 18.
14. Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete data. |
| Erasure ("right to be forgotten") | Request deletion of your personal data, subject to legal retention obligations. |
| Restriction | Request that we limit how we process your data in certain circumstances. |
| Portability | Request a machine-readable export of your personal data. |
| Objection | Object to processing based on legitimate interests or for direct marketing purposes. |
| Withdraw consent | Where processing is based on consent, withdraw that consent at any time. |
| Lodge a complaint | File a complaint with your local data protection supervisory authority. |
To exercise any of these rights, contact us at privacy@kynectlocal.com. We will respond within 30 days (or the timeframe required by applicable law). We may need to verify your identity before fulfilling a request.
If you are a franchisee employee or end user of a brand operating on KynectLocal, you should direct data subject requests to that brand directly, as they are the data controller for that data.
15. California Privacy Rights (CCPA / CPRA)
California residents have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Know — the categories of personal information collected, the purposes for collection, and the categories of third parties with whom it is shared.
- Delete — request deletion of personal information, subject to exceptions.
- Correct — request correction of inaccurate personal information.
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
- Limit use of sensitive personal information — we do not use sensitive personal information beyond what is necessary to provide the service.
- Non-discrimination — we will not discriminate against you for exercising any CCPA/CPRA rights.
To exercise California privacy rights, contact us at privacy@kynectlocal.com or use the contact information in Section 18. We will respond within 45 days as required by law. An authorized agent may submit a request on your behalf with proper written authorization.
Categories of Personal Information Collected (CCPA)
- Identifiers (name, email, IP address)
- Commercial information (subscription plans, billing history)
- Internet or other electronic network activity (request logs, usage data)
- Professional or employment-related information (role, business affiliation)
- Geolocation data (city/state level, derived from location profiles)
- Inferences drawn from the above to create a profile about platform usage
16. Children's Privacy
The KynectLocal platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data. If you believe we may have collected data from a child, contact us at privacy@kynectlocal.com.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to account holders at least 14 days before the changes take effect.
- Display a prominent notice within the platform admin interface.
Your continued use of the platform after the effective date constitutes acceptance of the updated policy. If you do not agree with any changes, you must cease use of the platform and may request account closure.
18. Contact Us
For questions, concerns, or to exercise your privacy rights, contact us:
Subject line: "Privacy Request — [Your Name]"
For GDPR-related inquiries from EEA/UK residents, include "GDPR Request" in your subject line.
We aim to respond to all privacy inquiries within 5 business days and to fulfill requests within 30 days (or the applicable legal deadline).